Skip to main content

Vendor/product archive

cloudfoundry / uaa_release CVEs

Beta · best-effort

5 CVEs tagged to cloudfoundry / uaa_release1 Critical, 3 High, 0 Medium, 1 Low, 0 Unrated.

CVE-2019-11279

Published Sep 26, 2019

CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes. A remote malicious user can escalate their ow…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3788

Published Apr 25, 2019

Cloud Foundry UAA Release, versions prior to 71.0, allows clients to be configured with an insecure redirect uri. Given a UAA client was configured with a wildcard in the redirect…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3775

Published Mar 7, 2019

Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address. A remote authenticated user can impersonate a different user by changing their email a…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1